CVE-2026-5435

The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gnu:glibc:*:*:*:*:*:*:*:*

History

05 May 2026, 17:38

Type Values Removed Values Added
First Time Gnu
Gnu glibc
References () https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u - () https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u - Third Party Advisory
References () https://sourceware.org/bugzilla/show_bug.cgi?id=34033 - () https://sourceware.org/bugzilla/show_bug.cgi?id=34033 - Issue Tracking
CPE cpe:2.3:a:gnu:glibc:*:*:*:*:*:*:*:*

28 Apr 2026, 16:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.3

28 Apr 2026, 13:19

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-28 13:19

Updated : 2026-05-05 17:38


NVD link : CVE-2026-5435

Mitre link : CVE-2026-5435

CVE.ORG link : CVE-2026-5435


JSON object : View

Products Affected

gnu

  • glibc
CWE
CWE-787

Out-of-bounds Write